Compliance · United States

HIPAA-ready AI that keeps PHI in your environment.

Clinical knowledge search, patient lines and documentation tools, running inside the covered entity’s infrastructure so PHI isn’t sent to an AI vendor.

Covers
Protected health information (PHI)
Rules
Privacy, Security, Breach Notification
Vendors
Business associate agreements
Our approach
No AI vendor in the PHI path

In short

HIPAA governs how covered entities and their business associates use and protect PHI. When an AI service processes PHI, it is typically a business associate and needs a BAA and Security Rule safeguards. Running the AI inside your own environment keeps PHI out of third-party AI services altogether.

What it asks

Requirements, and how we meet them.

RequirementHow DeepVox addresses it
Minimum necessary useAgents are scoped to the sources and roles that need them.
Security Rule safeguardsAccess control, audit logs and encryption options in your environment.
Business associatesNo AI vendor processes PHI; where we operate the system, appropriate terms are agreed.
Breach notificationLogs show exactly what was accessed, supporting investigation and notice.
Patient callsRecording notices, consent capture and retention controls for voice lines.

FAQ

Questions, answered.

Do we need a BAA with DeepVox?

If the system runs in your environment and we don’t access PHI, PHI isn’t disclosed to us. If we operate it for you with PHI access, we agree appropriate terms.

Can voice agents record calls?

Yes, with notice and consent. Some states require all parties to consent, so we configure notices per state.

Related

General information, not legal advice. Have your counsel confirm how each rule applies to you. Updated October 2026.

Start with two weeks of evidence, not a sales call.

A fixed-price discovery sprint, credited against whatever comes next. Or write to sales@deepvox.ai.

Book a discovery sprint